UK forging its own path while partly shadowing EU policies

As time goes by, emotions of the Brexit referendum 10 years ago recede into the past, the promised Brexit benefits disappear, and the UK economy flatlines. Now there will be a new UK Prime Minister, likely to be Andy Burnham, who is more open in is his pro-EU position than Prime Minister, Sir Keir Starmer. Economic growth may be his top priority, but he will certainly be aware of the need for digital regulation because of widespread concern over the negative impact of social media and related online services on children and other vulnerable groups.

The UK can forge its own path, for example, on social media policy and international transfers of personal data. UK regulators are monitoring EU policies and making an effort to work along compatible, but not identical, lines.

The good news is that the UK is travelling in the same direction as the EU.

Most companies want the direction of travel to be towards one regulatory framework for the UK and the EU. Fortunately, most political parties in the UK now support closer alignment with, or even re-joining, the EU.

The UK has adopted a slightly divergent model which enables it to explore new avenues. Some governments and national DPAs in the EU look with interest at the UK’s approach. But the European Economic Area (EEA) has to work as a unified bloc.

A role for the Cross Border Privacy Rules System

One area where the UK has diverged from the EU model is international transfers of personal data. The Cross Border Privacy Rules (CBPR’s) enforcement arrangement is administered by the USA and Japan. Its members include several Asia-Pacific countries, including perhaps surprising for some, Australia, Canada, New Zealand and Mexico.

The UK government is expressing its independence and divergence from the EU by becoming in 2023 an Associate Member of the APEC CBPR System joining other Associate Members Bermuda, Mauritius and Nigeria. So the UK is the first European country to do so.

The UK’s Chancellor of the Exchequer has declared that the government’s objective regarding international transfers is unlocking the value of the UK’s data assets to assist in economic growth, a prime industrial strategy goal.

The government’s momentum in this area is driven by the motivation to find a way, in effect, to expand the short list of EU “adequate” countries. Several ideas are proposed by Sanjana Shikhar, the winner of the PL&B Student Essay Competition.

A global CBPR-recognised type of Standard Contractual Clauses for international data transfers would be a way forward. The bad news is that the APEC CBPR System is criticised by privacy advocates as being too weak and having no legal force.

However, it enables the UK to explore new avenues for international transfers and develop data assets in a looser regulatory framework. The supervisory government department, The Department for Science, Innovation and Technology (DSIT), has advertised for applications for a “data transfer fellowship.”

Networking on international transfers is already happening:

  • Joining the CBPR gives the ICO a perfect opportunity for high level discussions with many national DPA representatives across the world.
  • ICO staff join discussions with other DPAs at OECD and G7 events. The aim is coordination with national DPAs, for example, on AI policy.

So the UK is not isolated from other European countries but neither does it have a seat around the table of the influential European Union’s Data Protection Board.

EU GDPR now open to some flexibility

The GDPR narrative is changing in the EU from “no changes” to flexibility. In the words of EU Justice Commissioner, Michael McGrath at our conference in Dublin, hosted by McCann FitzGerald in May: “.. legislation cannot remain static; it must evolve with the times. This is why, by harmonising and simplifying a limited number of provisions, we aim to provide clarity, and by making the framework easier to navigate and so easier to apply in practice, we aim to underpin confidence.”

He provided examples of how the proposals would deliver: simplification through burden reduction – by replacing 27 national lists on when to conduct Data Protection Impact Assessments with one single list at EU level; and simplification through proportionality – by requiring breach notifications to supervisory authorities only in high-risk situations.

Commissioner McGrath announced his plans to introduce a Digital Fairness Act (DFA) later this year. He placed his work on the DFA as a win for everyone “Looking at the ‘new horizon’ presented by the DFA, we are working towards a digital economy where our businesses are protected against unfair competition, consumers are protected against unfair practices, and our children are protected from unacceptable harms.”

I expect that not even the most ardent Brexiteer would argue with any of that.

DSIT will start recruitment for new IC Chair

Speaking at Parliament’s Science, Innovation and Technology Committee on 8 July, Liz Kendall, Secretary of State announced that the government will launch the recruitment drive for a new Chair of the Information Commission in mid-July. She said that the Department for Science, Innovation and Technology will soon announce the new Board of non-executive directors, most of whom will be women.

“We will also launch an independent review into the culture, accountability and governance of the ICO,” Kendall said. She said she has been appalled by the behaviour of the Information Commissioner who resigned over an independent investigation’s findings of sexual harassment and bullying.

Artificial Intelligence positive and disruptive

There are both positive and disruptive aspects of Artificial Intelligence and Agentic AI. Data Protection Officers tell us that AI (at the intersection of data systems, ethics, corporate values and law) is often added to their responsibilities. The fact is that everyone is in learning mode, as developments occur so quickly.

While AI can undoubtedly be a force for good, it is essential to keep “humans in the loop” to maintain your reputation. There have been at least 66 cases of AI hallucinated software/false citations (confirmed or suspected) in cases before the courts in the UK, reports barrister, Matthew Lee.(1) The judges have been very critical of the law firms involved and their reputations have been dented.

As the government has not committed to legislation on AI, the ICO is working on a code which will have clear legal status and the Digital Regulation Cooperation Forum is conducting research on how to manage risks with generative AI and agentic AI.

The ICO wants all parties to be clear on the distinguishing features of agentic AI compared with AI, such as enhanced autonomy and the ability to deploy “reasoning.” How do the GDPR principles apply, for example, accuracy, purpose limitation, storage period limitation, security, fairness and transparency?

Controllership and liability are not clear in complex use cases, such as recruitment, healthcare, and financial services. Typical questions for users are:

  1. How can a user identify and assess data protection risks?
  2. How to implement data protection by design?
  3. How should organisations manage governance and accountability to demonstrate compliance?

It is encouraging to know that the ICO is working harmoniously within the framework of the G7, and with the Netherlands and Spain’s DPAs on AI.

Meet the PL&B Report Correspondents

The next PL&B event is Meet the Correspondents on 6 October hosted by Slaughter and May in London, and will be free for subscribers to PL&B Reports.

The PL&B Team look forward to meeting you there

Stewart Dresner
Publisher, Privacy Laws & Business

July 2026

REFERENCE
  1. Natural and Artificial Intelligence in Law - 66 UK Cases of AI Hallucinated/False Citations (Confirmed or Suspected): The Lessons from Cork & Anor v Smith

News & Blogs

July 2026 Report Contents

Next